Hacker Warns Starbucks of Security Flaw, Gets Accused of Fraud
Andy Smith writes: Here's another company that just doesn't get security research. White hat hacker Egor Homakov found a security flaw in Starbucks gift cards which allowed people to steal money from the company. He reported the flaw to Starbucks, but rather than thank him, the company accused him of fraud and said he had been acting maliciously.
He would have been better off helping himself to free coffee until the wankers fixed their system.
Brackets contain world's first nanosig, highly magnified:[.]
Everyone knows that you get a negative reaction for stealing a small amount. Steal a couple million and you'll be respected.
Foamy the Squirrel nailed it.
"Egor Homakov did you a favor, I think you owe him a thank you, and an apology for your response to his discovery of a security flaw in your system.
This will be your only hope if another security flaw is found, and the discoverer of the flaw now ponders between letting Starbucks know (less likely after your response to Egor Homakov), not letting anyone know (which leaves the security flaw available for anyone to use), or letting the wrong people know about this flaw!
I feel like I am explaining something to a child. You are a corporation, act like one!"
It's pronounced "eye-gor."
Have gnu, will travel.
So docent this make starbucks liable
And the award for Worst Spellchecker of 2015 goes to...
I think Hitler tried something like that already.
more proof that responsible disclosure is foolish unless you are delaing with an organization you already have a solid IT/security relationship with.
in any other situation, just post the exploit kit anonymously and make a bowl of popcorn
Snowden and Manning are heroes.
Starbucks can have a new slogan.
Starbucks is a nasty company. Its CEO Howard Schultz is a fanatical Zionist; if you patronize Starbucks, you're supporting Israeli genocide.
Being a publicly traded company, the financial information is available, so go ahead and show on their financials where they are sending money to support Israeli genocide.
If you are not allowed to question your government then the government has answered your question.
Looks like we need a security wall of shame that lists the response to flaw disclosures of each organisation, so people can quickly determine which companies will fix a flaw upon receiving a report, and which companies are hostile and should not be contacted.
As there is no transcript of the phone call we have no idea what was actually said. It could have been something along the lines of "We try to guard against fraud and malicious behavior" or "continuing to do this could be considered fraud or malicious behavior". There is no proof the reporter was ever accused of either of those. Being accused makes a better story though.
Why would anyone use those? There's no discount. A $25 gift card just entitles you to spend $25 worth of whatever that company has to sell. What's the point? To show someone that you know that they like coffee, so instead of giving them $25 you give them a $25 Starbucks gift card? It's not really more thoughtful than giving cash yet it's far less convenient for everyone involved. And why would you even refill those for yourself? Because you don't trust yourself with your own money?
And a Starbucks gift card is not like those gas credit cards, the last resort of degenerate gamblers, junkies and broke-ass idiots who offer you to fill up your car using their card in exchange for $20 cash. At least those are convenient if you happen to stop for gas at the right place and the right time.
Fuck gift cards.
lucm, indeed.
When a BIG CO is confronted with a security flaw, by someone outside the CO, they react in anger first, then fear, then they turn one the person/persons who confronted them. When you distill all the emotional cruft, it's that their pride was hurt. Never mind someone did "their" homework for them. They want to"save face".It makes them angry that YOU did something they should have done. No sharing of information for the common good, with arrogant pricks.:)